Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.760 exploits
GitHub PoC1
Public PoC for CVE-2026-82222
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC4
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
CVE-2026-78904CRITICAL30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
48RIESGO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2025-5777CRITICALbajo ataqueransomware30 ago 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RIESGO
abrir
GitHub PoC
Shellshock CVE-2014-6271 vulnerable CGI lab
CVE-2014-6271CRITICALbajo ataque30 ago 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC2
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
CVE-2026-78905HIGH30 ago 2026
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL30 ago 2026
NGINX ngx_http_rewrite_module vulnerability
60RIESGO
abrir
GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
CVE-2026-60004CRITICALbajo ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC
CVE-2026-45833 ChromaDB
CVE-2026-45833CRITICAL30 ago 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
48RIESGO
abrir
GitHub PoC
Log4Shell CVE-2021-44228 vulnerable lab
CVE-2021-44228CRITICALbajo ataqueransomware30 ago 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
CVE-2026-63030CRITICALbajo ataque30 ago 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RIESGO
abrir
GitHub PoC16
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
GitHub PoC1
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
CVE-2026-80724HIGH30 ago 2026
ptp: vmclock: prevent read-only mappings from becoming writable
41RIESGO
abrir
GitHub PoC
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
CVE-2026-8452HIGHbajo ataque30 ago 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RIESGO
abrir
GitHub PoC
Balboa form Command Injection POC
CVE-2026-67363HIGH30 ago 2026
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
41RIESGO
abrir
GitHub PoC1
PoC CVE-2026-18741
CVE-2026-18741MEDIUM30 ago 2026
Worksuite SaaS version prior to 6.0.14 Stored XSS via Asset Management Location and Description Fields
33RIESGO
abrir
GitHub PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
CVE-2026-60004CRITICALbajo ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 ago 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir
GitHub PoC
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
CVE-2026-12513MEDIUM30 ago 2026
Shared Files < 1.7.68 - Unauthenticated Arbitrary File Deletion via Path Traversal
33RIESGO
abrir
GitHub PoC2
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
CVE-2026-78903LOW30 ago 2026
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-60004CRITICALbajo ataque30 ago 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RIESGO
abrir
GitHub PoC
CVE-2026-76581
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL30 ago 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RIESGO
abrir
GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-56121
CVE-2026-56121CRITICAL30 ago 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RIESGO
abrir
GitHub PoC
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
CVE-2026-76581CRITICAL30 ago 2026
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC1
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
CVE-2026-79483MEDIUM30 ago 2026
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistor
33RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2026-82222CRITICAL30 ago 2026
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RIESGO
abrir
GitHub PoC
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
CVE-2018-7600CRITICALbajo ataqueransomware30 ago 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
Hunt-Benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack
CVE-2026-68929CRITICAL29 ago 2026
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
48RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.